This is a fully remote position; however, candidates located in Morrisville, NC, Falls Church, VA, or Eagan, MN will be given preference.
Disclaimer:
- No third-party agencies will be considered. Please do not solicit our team.
- Due to the nature of the position supporting a federal or government contract, candidates must be U.S. citizens and eligible to work on a W2 basis.
Description:
We’re looking for an experienced Penetration Tester to join our security team and lead advanced offensive security assessments across web applications, APIs, networks, and enterprise environments. In this role, you’ll plan and execute penetration tests, red team engagements, and purple team exercises to uncover vulnerabilities, validate defensive controls, and strengthen overall security posture.
You’ll work across a wide range of testing scenarios, including web and API assessments, network penetration testing, phishing and lateral movement activities, AI‑enabled testing, and PCI‑DSS engagements. The ideal candidate has strong hands‑on experience with tools like Burp Suite Professional, Kali Linux, Metasploit Pro, and Cobalt Strike, along with scripting capabilities in Python or PowerShell. You’ll collaborate closely with engineering and CSOC teams and deliver clear, detailed reports that communicate attack paths and actionable remediation guidance.
Responsibilities:
• Conduct penetration tests across web applications, APIs, networks, and enterprise environments.
• Execute red team engagements from planning through exploitation, lateral movement, and reporting.
• Perform phishing campaigns to assess user susceptibility and support threat‑emulation activities.
• Leverage tools such as Burp Suite Pro, Kali Linux, Metasploit Pro, Cobalt Strike, and AI‑based testing platforms.
• Develop and execute custom scripts (Python or PowerShell) to support exploitation and automation.
• Participate in purple team engagements to evaluate and improve monitoring and detection controls.
• Support PCI‑DSS penetration testing, documentation, and compliance activities.
• Produce high‑quality technical reports that clearly communicate vulnerabilities and attack chains.
• Apply frameworks such as OWASP ASVS and MITRE ATT&CK throughout testing and reporting.
• Stay current on emerging threats, offensive techniques, and penetration testing tooling.
Qualifications:
• Minimum of eight (8) years of relevant penetration testing or offensive security experience.
• Bachelor’s degree in a related field; an additional four years of relevant experience may substitute for a non‑related degree.
• Strong expertise in web application testing, API testing, and network penetration testing.
• Experience with dynamic analysis tools such as Burp Suite Professional or similar DAST platforms.
• Hands‑on experience with AI‑based penetration testing methods.
• Advanced proficiency with Kali Linux and its penetration testing toolsets.
• Experience using tools like Metasploit Pro and Cobalt Strike for red team operations.
• Experience planning and executing full red team engagements.
• Experience performing phishing operations and conducting lateral movement within enterprise networks.
• Experience in purple team exercises involving engineering teams and CSOC analysts.
• Proficiency in scripting languages such as Python and/or PowerShell.
• Experience performing penetration testing in PCI‑DSS environments.
• Strong technical writing and communication skills; able to explain vulnerabilities and attack paths clearly.
• Familiarity with OWASP ASVS and MITRE ATT&CK frameworks.
Certifications (Desired):
Acceptable certifications include:
• Offensive Security Certified Professional (OSCP)
• GIAC Certified Penetration Tester (GPEN)
• GIAC Web Application Penetration Tester (GWAPT)
• GIAC Exploit Researcher and Advanced Penetration Tester (GXPN)
Penetration Tester in Morrisville at ManpowerGroup
This position is listed as contract and able to be worked remotely. It was posted 2 days ago.